Skip to main content
VISO TRUST’s risk model is configurable. While the underlying scoring methodology is consistent, you can tune how risk scores map to labels and how strict the thresholds are — so the output aligns with how your organization thinks about and communicates risk. There are two places to look:
  • Settings → Risk Model shows your current tolerance, the score thresholds behind each risk label, and how your portfolio is distributed across those labels. It’s a read-only view.
  • Settings → Your Framework → Risk calculations is where the settings are changed. Editing requires the Admin role and happens on a framework draft, so nothing takes effect until you publish.

Risk Tolerance

Risk tolerance determines how demanding the model is when translating numeric risk scores into labels like Low, Medium, High, and Extreme. It controls the thresholds at which a vendor’s score crosses from one label to the next. VISO TRUST offers three predefined tolerance levels:

Minimal

Default. The strictest setting. High-assurance artifacts (independent audits, certifications) are required to move a vendor into the lowest risk tier. Best for organizations in regulated industries or those handling highly sensitive data with mature TPRM programs.

Moderate

Balances security rigor with operational efficiency. Strong controls are expected but there’s more flexibility in the assurance level required. Suited for mid-sized or fast-growing organizations with dynamic vendor portfolios.

Significant

Accepts a higher level of risk in exchange for speed and flexibility. Focus is on core security controls, with questionnaire responses accepted as primary evidence. Suited for less regulated industries or early-stage TPRM programs.
Publishing a risk tolerance change re-runs the risk model for every relationship in your organization, so scores and labels across your portfolio can move at once — a vendor labeled “Low” under Minimal tolerance may land differently under Significant. Review your portfolio after publishing.

Risk Label Names

The default labels — No Context, Low, Medium, High, Extreme — can be renamed to match your organization’s risk vocabulary. If your GRC framework or executive reporting uses different terminology, updating the labels ensures consistency. Renaming happens in the same place as tolerance: in Settings → Your Framework → Risk calculations, select Customize on the risk tolerance card, then fill in the Custom label field for each level alongside its default label. Label name changes are cosmetic only — they don’t affect the underlying scoring or thresholds.

Control Domain Weighting

Every control domain carries a weight. In-scope domain weight is what sets a relationship’s likelihood, and each individual control inherits a share of its domain’s weight — so a heavy domain moves the score more than a light one, both when it comes into scope and when evidence satisfies it. A vendor with network access is therefore scored differently from one with only data access. For organizations using Custom Frameworks, control domain weighting can be adjusted to reflect your program’s priorities — for example, placing greater weight on privacy controls for vendors handling personal data. To see the weights in effect on a specific vendor, open the relationship’s risk analysis — the likelihood step shows in-scope weight against total weight, and each control detail shows its own weight.

Risk Overrides

When an assessment is in Review Risk status, Admins and Program Managers can manually override the inherent or residual risk value calculated by the model — as can Contributors on relationships where they’re the Business Owner or Assessment Lead. Use this when:
  • Compensating controls have been implemented that aren’t captured in the assessment
  • The relationship context doesn’t fully reflect the actual risk exposure
  • A business decision warrants accepting a different risk level than the model suggests
Overrides are documented in the relationship’s activity log and remain in effect until the next assessment update.

Risk Model Updates

When VISO TRUST updates the risk model itself, a relationship shows a Risk model updated pending change if the model version behind its last completed assessment differs from the version behind its current scores. Existing assessments are left alone — each one keeps rendering under the model it was calculated with — and the new model takes full effect the next time an assessment update runs.

Compliance Certification Influence

By default, VISO TRUST gives partial credit when a vendor publicly claims a compliance certification (e.g., displays a SOC 2 badge on their website) but hasn’t provided the actual report. This reduces residual risk slightly, with lower assurance than a validated artifact. You can disable this behavior so that compliance certifications only count when the actual report is submitted and reviewed. The Include compliance certifications in risk calculations toggle is in Settings → Your Framework → Risk calculations, and like risk tolerance it applies when you publish the draft.

What the Risk Model Doesn’t Do

  • It doesn’t replace human judgment. Risk overrides, context configuration, and remediation decisions are all made by your team.
  • It doesn’t assess vendors you don’t have relationships with. Scores only exist for vendors in your portfolio.
  • It doesn’t guarantee outcomes. Risk scores reflect the evidence collected — they’re as accurate as the data behind them.